Hackers are leaking sensitive personal - (PII) and protected health information (PHI) from India’s top health insurance company, Star Health and Allied Insurance, via Telegram chatbots.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Indian government subjects phone makers to cyber security standards and are required to report their hardware, software and network security measures by August 28th.
The secret order, issued in late November, would have made India’s security app a mandatory inclusion on all new devices from smartphone makers within 90 days. Smartphone makers would have also been required to push it to older devices that are still supported via a security update.
Indonesia’s tax agency, the Directorate General of Taxes (DJP), has suffered a data breach impacting 6 million people, including President Widodo, his family, and cabinet members.
In total, the cyber attack on Indonesia’s national data center impacted about 200 government agencies. Travel and immigration saw the most dramatic impacts, but also received priority attention and have largely been restored at this point.
Realizing the growing danger that insider attacks pose to businesses and national security, National Insider Threat Awareness Month has become an annual call for organizations to take preventative actions in an effort to minimize their risk of attacks.
It’s important that businesses monitor Dark Web trends and activity to monitor what data has been breached and understand where there might be weak links at the employee and enterprise level.
In a massive data leak, details of 115 million Pakistani mobile subscribers have surfaced online after a hacker tried to sell the package for 300 bitcoins equivalent to $2.1 million.
Infosec firm Qualys admitted it was an Accellion FTA data breach victim but denied experiencing a ransomware attack after the Clop ransomware gang published customer order documents.
DarkSword packs both a complete iOS exploit chain and infostealer into one package. The chain initiates when Safari opens a malicious webpage with a hidden iframe that springs the malware from the WebContent sandbox. It then works its way into deploying a number of custom payloads designed to tap into various vital and privileged iOS services.










